216.73.216.145

Ongoing PLC Exploitation Against Critical U.S. Infrastructure

· Published 24/07/2026 14:34

Export JSON

Essential information

Published
24/07/2026 14:34
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
critical infrastructure energy sector hmi manipulation industrial control systems iocontrol irgc-cec malpdb ot security plc exploitation water facilities
Related entities
23 indicators, 23 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware

Description

Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. . Attackers scan for internet-exposed and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818.

External references